Privacy Policy
Last updated: September 2026
1. Who we are
Upfayre is a web and mobile platform that helps school PTAs, sports clubs, community groups and similar fundraising organisations plan events. It is operated by One Tandem Limited, a company registered in England and Wales (company number 17229064), trading as Upfayre. You can contact us at [email protected].
We are the data controller for personal data processed through this service. We are registered with the Information Commissioner's Office (ICO) under registration number ZC156390.
The organisation you belong to, or buy from, is a separate controller of the information you give it — for example your committee can see the tasks you take on, and a shop can see what you ordered. This policy covers what Upfayre does with your data.
This policy explains what personal data we collect, why we collect it, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. What data we collect and why
Account information
When you register, we collect your full name, email address, and a hashed (non-recoverable) password. You may also provide a display name and a profile photo. This information is necessary to provide you with an account and to identify you to your colleagues on the platform.
Lawful basis: Contract — this data is needed to fulfil the service you've signed up for.
Sign-in activity
We record the date and time of your last two sign-ins and the associated IP addresses, and look up the country each address belongs to (via ipinfo.io — see section 4) so an administrator can spot a sign-in from an unexpected place. We also use how recently you last signed in to gauge how active your account is — for example, to send an occasional reminder to a committee member or event admin who hasn't been active for a while, and to decide when a never-confirmed, unused account should be paused and eventually removed (see section 5). You can turn reminder emails off at any time.
Lawful basis: Legitimate interests — protecting the security of user accounts, keeping active organisers engaged, and not retaining accounts that were never used.
School and event activity
We store the content you create while using Upfayre: school memberships, events you create or join, tasks you create or are assigned, chat messages and reactions, files you upload (such as posters, risk assessments and supplier quotes), volunteer rota sign-ups, event costs and receipts you log, and any retrospective notes. This content is necessary to provide the core features of the service and is visible to the other members of your organisation according to their role.
Lawful basis: Contract.
Notification preferences
We store your email notification preferences (for example, whether you want to receive task reminders, occasional get-started tips and reminders, or a weekly digest). This allows us to send you only the communications you have opted into.
Lawful basis: Contract.
Contact form submissions
When you contact us via the contact form, we collect your name, email address, and message so we can respond to your enquiry.
Lawful basis: Legitimate interests — handling your request.
Storefront purchase data (buyers)
When you make a purchase through an organisation's public storefront, we collect your name, email address, and order details (items purchased, quantities, price paid, payment reference, and the answers to any questions the organisation asked at checkout, such as a child's class for a ticket). This data is shared with the organisation (the merchant of record) so they can fulfil your order and handle any refund requests. It is also processed by Stripe to handle the payment — see section 4.
You do not need an Upfayre account to make a purchase. Your buyer data is held separately from Upfayre account data and is not used for any marketing purpose.
Lawful basis: Contract — this data is necessary to process and fulfil your purchase.
Helpers added by a committee, and public volunteer sign-ups
Committees can add people who don't have an Upfayre account — a parent who has offered to run a stall, say — so they can be given tasks or rota slots. For these people we hold a name, and an email address and/or phone number if the committee provides one. Parents who sign up for a volunteer slot from a public rota link give us their name and email address so the organiser can confirm the slot and we can send a reminder before the shift. If you later create an Upfayre account with the same email address, these records are linked to it.
Lawful basis: Legitimate interests — running the organisation's event. You can ask the organiser or us to remove you at any time.
Event feedback
After an event, organisers can invite guests and team members to leave feedback (star ratings and comments) through a shared link. Responses are stored against the event. Guest responses are de-duplicated using a one-way hash rather than an account, and are shown to the committee without a name unless you choose to give one.
Lawful basis: Legitimate interests — helping the organisation improve its next event.
Push notifications
If you install the iOS or Android app and allow notifications, we store a device token issued by Apple or Google so we can deliver notifications (such as an @mention in chat) to that device. Tokens are removed when you delete your account, and after six months without the app being opened on that device.
Lawful basis: Contract — delivering the notifications you've turned on.
Marketing attribution
If you arrived through a tagged marketing link (see section 3) and then register, the campaign tags from that first visit are stored against your account so we can see which channels bring real committees to Upfayre. If you accepted analytics cookies, we also tell Meta and Google that a sign-up from their link completed, using a hashed version of your email address together with your IP address and browser details; we never send them your name or address in the clear. If you rejected cookies, nothing is sent.
Lawful basis: Legitimate interests (our own first-party attribution); Consent (sharing a sign-up event with Meta or Google).
Rewards programme submissions
If you submit a testimonial, video or social post for our rewards programme, we store what you submit together with your name and organisation so we can credit it. Our Terms of Service explain how we may use it and how to withdraw it.
Lawful basis: Contract (the rewards programme terms you accept when you submit).
Support access by Upfayre staff
To investigate a problem you've reported, an Upfayre administrator can temporarily view the app as your account. Every such session is recorded in an audit log (who, whose account, when) and we only do it in response to a support request or a suspected fault.
Lawful basis: Legitimate interests — supporting you and keeping the service working.
3. Cookies
We use a small number of first-party cookies: a session cookie that keeps you signed in (and carries the security token that protects against cross-site request forgery), a "remember me" cookie, and a cookie that records your choice on the cookie banner.
We also use three third-party analytics tools — Google Analytics 4, the Meta Pixel and Contentsquare — but only if you click Accept on the cookie banner. If you reject, none of them load and no third-party cookies are set. Rejecting is one click, the same as accepting.
If you arrive at our site via a link that includes campaign tags (for example a UTM-tagged link we share, or a link clicked from a social platform such as Facebook), we set two further first-party cookies so we can understand which channels bring people to Upfayre:
- a visitor identifier (random value, kept for up to one year)
- a first-touch attribution record (the campaign tags from your first landing, kept for up to 90 days)
These two cookies are first-party only and, by themselves, send nothing to anyone else. See "Marketing attribution" in section 2 for what happens if you accept analytics cookies and go on to sign up. If you sign up, the attribution is stored against your account and you can request its deletion under section 6.
For the full list of cookies, including the ones the analytics tools set, see our Cookie Policy.
4. Who we share your data with
We do not sell your data. We share it only with the following data processors, who act on our instructions and are bound by data processing agreements. Three of them (Meta, Google Analytics and Contentsquare) receive nothing unless you accept analytics cookies.
- Scalingo — our cloud hosting provider (servers located in France, EU). Your account data, event data, chat messages and background jobs live in a PostgreSQL database managed by Scalingo, which also holds our automated backups. Scalingo DPA →
- Cloudflare — every request to Upfayre passes through Cloudflare's network, which protects the site against attacks and serves Turnstile, the bot check on our sign-up and contact forms; Cloudflare therefore sees your IP address and request details in transit. Files you upload (profile photos, logos, event documents, chat attachments) are stored in Cloudflare's R2 object storage. Cloudflare is subject to the UK International Data Transfer Agreement framework. Cloudflare Privacy →
- Brevo — we use Brevo (formerly Sendinblue) to send transactional emails, including notifications, invitations, and password reset emails, and Brevo tells us whether each email was delivered or opened. Brevo is based in the EU. Brevo Privacy →
- Stripe — we use Stripe to process payments made through organisation storefronts, and to bill organisations for the Full plan. When you purchase through a storefront, Stripe receives your payment details and order data on behalf of the organisation (who is the merchant of record). Stripe acts as a data controller for your payment data under its own privacy policy. Stripe is certified under the EU–US Data Privacy Framework and subject to the UK International Data Transfer Agreement framework. Stripe Privacy →
- Apple and Google (push notifications) — if you use the apps and allow notifications, the content of each push notification and your device token are relayed through Apple's Push Notification service or Google's Firebase Cloud Messaging. Apple Privacy →
- Meta (opt-in) — if you accept analytics cookies, the Meta Pixel runs in your browser and we send matching events to Meta's Conversions API from our server (a hashed email address, your IP address, browser details and the click identifier from a Meta ad) so we can measure whether our advertising works. Nothing is sent if you reject. Meta is US-based; transfers are covered by the UK International Data Transfer Agreement framework. Meta Privacy →
- Google Analytics 4 (opt-in) — if you accept analytics cookies, Google Analytics receives page views and events (such as a sign-up completing) so we can see how the site is used in aggregate. Google is US-based; transfers are covered by the UK International Data Transfer Agreement framework. Google Privacy →
- Contentsquare (opt-in) — if you accept analytics cookies, Contentsquare records anonymised sessions — clicks, scrolling and page flow, with form inputs masked — so we can see where the app is confusing. Contentsquare is based in the EU. Contentsquare Privacy →
- GlitchTip — our error-reporting service receives details of application errors: the page, the error, and an internal user identifier if you were signed in — never your password, message content or form contents. GlitchTip Privacy →
- ipinfo.io — we send the IP addresses recorded at sign-in to ipinfo.io to look up the country they belong to, for the security check described in section 2. ipinfo.io is US-based. ipinfo.io Privacy →
- Slack — we use Slack for our own internal alerts. Some alerts contain personal data so our team can act promptly — a new sign-up alert includes the name and email address of the person who registered, and an account-deletion alert the address that was deleted. Slack is US-based; transfers are covered by the UK International Data Transfer Agreement framework. Slack Privacy →
- Anthropic — when a committee chooses to generate a summary of the feedback collected after an event, we send that feedback (the star ratings and the comments themselves) to Anthropic's Claude API to produce the summary. We do not send respondents' names, email addresses or account identifiers. Under Anthropic's commercial API terms, the data is not used to train its models. Anthropic is US-based; transfers are covered by Standard Contractual Clauses under its data processing agreement. Anthropic Privacy →
Where processors are outside the UK, we ensure appropriate safeguards are in place (such as the UK International Data Transfer Agreement, UK-approved Standard Contractual Clauses, or an adequacy decision).
We may also disclose data where required by law, or to protect the safety or rights of users or the public.
5. How long we keep your data
- Account data — retained for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we are required to retain it for legal or audit purposes (see the entries below).
- Unconfirmed accounts — if you create an account but never confirm your email address and never use it, we stop emailing you and then, after around seven months of inactivity and a final reminder, delete the account and the personal data attached to it.
- Event and task data — retained as part of the organisation's records for as long as the organisation has an active account on Upfayre.
- Chat messages — retained as part of the event record. When an event is archived, messages are retained but the event is marked as read-only. Attachments on deleted messages are removed by a nightly clean-up.
- Files you upload — deleted when the file, event or organisation record they belong to is deleted.
- Sign-in IP addresses — overwritten on each new sign-in; we retain only the two most recent.
- Email delivery logs — we keep a record of each email we send (recipient address, subject line and delivery status; never the body) for 12 months, to diagnose delivery problems and honour unsubscribe and bounce signals, after which the record is deleted.
- Marketing attribution records — the record of a tagged-link visit (campaign tags, IP address, browser details) is kept for 13 months so we can compare year on year, then deleted. The campaign tags stored against your account stay with the account.
- Administrative audit records — records of administrative actions, including support access to an account, are kept for as long as the service operates, as our accountability record.
- Contact form messages — delivered to our mailbox and kept there for up to 12 months after the enquiry is resolved.
- Order and transaction data — retained for 7 years from the date of purchase, in line with HMRC financial record-keeping requirements. Buyer name and email are retained for the same period for the purposes of dispute resolution and refund processing.
- Backups — our hosting provider takes automated database backups that are overwritten on a rolling basis, so deleted data can persist in a backup for a limited period before it is overwritten.
6. Your rights
Under UK GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you. Signed-in users can download their account data from their profile settings.
- Rectification — ask us to correct inaccurate data. You can also update most of your data directly in your account settings.
- Erasure — ask us to delete your personal data ("right to be forgotten"), subject to any legal obligations we have to retain it. You can delete your own account from your profile settings, or from our account deletion page if you can't sign in.
- Portability — receive your personal data in a structured, machine-readable format.
- Restriction — ask us to restrict processing of your data in certain circumstances.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, you can withdraw it at any time. For analytics cookies, clear the
cookie_consentcookie and choose Reject when the banner reappears.
To exercise any of these rights, email us at [email protected]. We will respond within one calendar month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
7. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you. We do group accounts by how recently they were active to decide which reminder or tips emails to send; that grouping has no other effect and you can turn those emails off.
8. Children's data
Upfayre is a tool for the adult committee members of the organisations that use it. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has registered, please contact us immediately and we will delete the account.
9. Changes to this policy
We may update this policy from time to time. If we make a material change, we will notify registered users by email before the change takes effect. The date at the top of this page will always reflect the most recent version.
10. Contact us
Questions about this policy or your data? Email us at [email protected] or use the contact form.